{ "version": "4.1", "name": "Detection Coverage", "description": "security_content detection coverage", "domain": "mitre-enterprise", "techniques": [ {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {}, {}, { "techniqueID": "T1053.005", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_scheduled_task_from_public_directory.yml" }, {}, {}, {}, { "techniqueID": "T1047", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1113", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1218.011", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1592", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1003", "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1123", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1543", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1548.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1114", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml" }, { "techniqueID": "T1003.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.011", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1071.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1547", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1489", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204.002", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1543.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1566.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1007", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, { "techniqueID": "T1530", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_open_s3_buckets_over_aws_cli.yml" }, {}, {}, { "techniqueID": "T1135", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1222.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, { "techniqueID": "T1082", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml" }, {}, {}, { "techniqueID": "T1053", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, { "techniqueID": "T1590.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1106", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1202", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, { "techniqueID": "T1140", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, {}, {}, {}, {}, { "techniqueID": "T1190", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1558", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1555", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1036", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { "techniqueID": "T1546.011", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1552", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, { "techniqueID": "T1547.010", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/monitor_registry_keys_for_print_monitors.yml" }, {}, { "techniqueID": "T1055", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_searchprotocolhost_no_command_line_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1021.002", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1525", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_gcr_container_uploaded.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1562.004", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1021", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1595.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1207", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1112", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1535", "score": 8, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml" }, {}, { "techniqueID": "T1563", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1505.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1136.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml" }, {}, { "techniqueID": "T1070.001", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" }, {}, {}, {}, { "techniqueID": "T1003.001", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml" }, {}, {}, { "techniqueID": "T1595", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1548", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1117", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1546.012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1016", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml" }, {}, {}, { "techniqueID": "T1546.008", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml" }, {}, {}, { "techniqueID": "T1087", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, {}, { "techniqueID": "T1059", "score": 18, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" }, {}, {}, {}, { "techniqueID": "T1482", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1562.007", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_network_acl_activity.yml" }, {}, {}, {}, { "techniqueID": "T1070", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1083", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1114.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_user_email_forwarding.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.005", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1204", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1057", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1546.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml" }, {}, {}, {}, { "techniqueID": "T1072", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, { "techniqueID": "T1591", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1554", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml" }, { "techniqueID": "T1059.001", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/nishang_powershelltcponeline.yml" }, {}, { "techniqueID": "T1546.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1590", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml" }, { "techniqueID": "T1210", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1547.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml" }, { "techniqueID": "T1199", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1136.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, {}, { "techniqueID": "T1098", "score": 12, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1566", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_email___uba_anomaly.yml" }, {}, {}, { "techniqueID": "T1218.001", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml" }, { "techniqueID": "T1070.005", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml" }, {}, { "techniqueID": "T1110", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, {}, {}, {}, { "techniqueID": "T1562.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml" }, {}, {}, {}, { "techniqueID": "T1039", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, {}, {}, { "techniqueID": "T1574", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1078", "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1068", "score": 9, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1027", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml" }, { "techniqueID": "T1114.002", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" }, {}, {}, {}, { "techniqueID": "T1201", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1486", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1218.010", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, {}, {}, { "techniqueID": "T1592.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1589.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, {}, { "techniqueID": "T1036.003", "score": 7, "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { "techniqueID": "T1203", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml" }, {}, {}, {}, {}, { "techniqueID": "T1574.009", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1012", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, { "techniqueID": "T1078.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml" }, { "techniqueID": "T1218.009", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_regsvcs_with_no_command_line_arguments.yml" }, {}, {}, { "techniqueID": "T1553.004", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1127.001", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1585", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1569", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { "techniqueID": "T1059.003", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1485", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1189", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1134", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1071.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml" }, {}, {}, {}, {}, { "techniqueID": "T1136", "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, { "techniqueID": "T1526", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml" }, {}, {}, { "techniqueID": "T1046", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1518", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, {}, {}, {}, {}, { "techniqueID": "T1550.002", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml" }, {}, {}, { "techniqueID": "T1105", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1484", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1564.001", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, {}, {}, {}, {}, {}, { "techniqueID": "T1003.003", "score": 6, "comment": "https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml" }, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1078.004", "score": 17, "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, {}, { "techniqueID": "T1558.003", "score": 2, "comment": "https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1556", "score": 3, "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_excessive_sso_logon_errors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml" }, {}, {}, { "techniqueID": "T1490", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { "techniqueID": "T1566.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, { "techniqueID": "T1048.003", "score": 4, "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, {}, {}, { "techniqueID": "T1078.003", "score": 1, "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml" }, {}, { "techniqueID": "T1127", "score": 5, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, {} ], "gradient": { "colors": [ "#ffffff", "#66b1ff", "#096ed7" ], "minValue": 0, "maxValue": 24 }, "filters": { "platforms": [ "Windows", "Linux", "macOS", "AWS", "GCP", "Azure", "Office 365", "SaaS" ] }, "legendItems": [ { "label": "NO available detections", "color": "#ffffff" }, { "label": "Some detections available", "color": "#66b1ff" } ], "showTacticRowBackground": true, "tacticRowBackground": "#dddddd", "sorting": 3 }